Effective Date: July 20, 2026
Last Updated: October 6, 2026
This Privacy Policy explains how TaxPulse Incorporated ("TaxPulse," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the TaxPulse platform (the "Service"). Because TaxPulse is used by tax professionals who handle highly sensitive client information, protecting that information is central to our Service.
This policy describes our practices for (a) the tax professionals and firms who hold accounts with us ("Customers" or "you"), and (b) visitors to our website. Information about a Customer's own clients ("taxpayer information") is processed by us on the Customer's behalf and is governed primarily by our Data Processing Agreement; the Customer is responsible for its own privacy practices toward its clients.
We use information to:
We do not sell taxpayer information. We process taxpayer information only as needed to provide the Service to you and consistent with IRC §7216 and §6713 and our Data Processing Agreement.
The Service lets you or your client securely connect a financial account to import information relevant to tax preparation. When an account is connected, we receive financial account data (which may include account and routing numbers, balances, and transaction history) through a trusted third-party financial data provider, and only after the account holder authorizes the connection through that provider.
We use this information solely to provide the features you request (for example, importing income or reconciling transactions) and to secure and operate the Service. We do not sell financial account data. Login credentials for connected institutions are never received or stored by us: the connection is tokenized, and any access tokens and account numbers we retain are encrypted at rest. The third-party provider's handling of the data is governed by that provider's own privacy policy, and you may disconnect a linked account at any time.
You may choose to connect a Google account so that appointments booked through TaxPulse appear in your calendar. This is optional, and the Service works without it.
When you connect, we request a single Google Calendar scope (https://www.googleapis.com/auth/calendar.events) and use it for two things only: to create and update calendar events for appointments booked through TaxPulse, and to read the events already on the calendar you selected so that your schedule in TaxPulse matches your real day and we do not offer a client a booking slot when you are not free.
Please read this part before you connect. The synchronisation runs in both directions, so the events we read are copied into your TaxPulse schedule, not only checked for availability. For each event on the connected calendar within roughly seven days behind and thirty days ahead of today, we store its title, start time, length, cancellation state and Google event identifier as an entry in your TaxPulse schedule. That includes personal events, under whatever name you gave them, and those entries can be seen by people at your firm who are permitted to view your schedule in TaxPulse. If your calendar holds appointments you would rather your colleagues not see, connect a calendar you keep for work instead of your personal one, or leave the integration switched off. You can disconnect at any time, as described below.
Beyond those entries we store only what is needed to keep the connection working: an access token, a refresh token, the identifier of the calendar you selected, and the time we last synced. We do not use Google user data for advertising, we do not sell or transfer it, and we do not use it to train artificial-intelligence or machine-learning models. TaxPulse's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from Calendar Manager inside TaxPulse, or by removing TaxPulse at myaccount.google.com/permissions. When you disconnect through TaxPulse we revoke the token with Google and delete the stored tokens from our systems. Events already written to your calendar remain yours and are not removed.
An office may choose to connect its own social media accounts so it can publish its own posts from TaxPulse. The networks are Facebook Pages, Instagram professional accounts linked to a Facebook Page, LinkedIn, X, TikTok, Pinterest and Google Business Profile. Connecting is optional, each network asks you to approve access on its own screen, and the Service works without it.
What we receive and store. For each account you connect we store the network's identifier for the account, its name or handle, its profile picture address, the permissions you granted, and the access token (and, where the network issues one, the refresh token) that lets us post on your behalf. In addition:
https://www.googleapis.com/auth/business.manage scope. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.What we do with it. We use this access only to publish the posts your office writes in TaxPulse, to the accounts your office chooses, when someone at your office publishes a post or when a post your office scheduled comes due. That includes the text, the image or video address and the link in the post, and, if the post has one, a first comment beneath it on Facebook, Instagram, LinkedIn or X. We keep tokens current by asking the network for a new access token before it expires. We do not read your feed, messages, comments, followers, mentions or insights from any network, and we do not post anything your office did not write or schedule. Until TikTok completes its review of TaxPulse, posts sent to TikTok are published as private, visible only to the account owner.
How it is protected and shared. Access and refresh tokens are encrypted at rest and are used only by our servers. We do not sell social account data or use it for advertising, we do not share it with anyone except the network it came from, and we do not send it to any AI provider or use it to train artificial-intelligence or machine-learning models.
Disconnecting and deletion. You can disconnect an account at any time from Social, then Connected Accounts, inside TaxPulse. Disconnecting immediately erases the stored access and refresh tokens; for X, TikTok and Google Business Profile we also ask the network to revoke the access. You can also remove TaxPulse in the network's own settings. If you remove TaxPulse in Facebook, Facebook notifies us and we erase the tokens for the accounts you connected; if you also ask Facebook to delete your data, Facebook sends us that request and we delete every Facebook Page and Instagram record you connected and give Facebook a confirmation code and a status page. For any network you may ask us to delete the data we hold by writing to support@taxpulse.biz. Full instructions are on our Social Account Data Deletion page. Posts already published on a network stay there until you delete them on that network.
Parts of the Service use artificial intelligence: reading an uploaded document to pull figures onto a return, reading an identification document, categorising bank transactions, explaining an IRS notice, drafting a message, and the in-app assistant. Where you use one of these features, the information needed to answer that request is sent to our AI provider. Depending on the feature, that may include taxpayer information such as the contents of a tax document, an identification document, or transaction history.
Our AI provider acts as our service provider and processes this information only to return the result you asked for. It is contractually prohibited from using it to train its models, and we do not use taxpayer information to train models of our own. These features are part of preparing the return you asked us to help with, and are covered by the consent you obtain from your client under IRC §7216 and by our Data Processing Agreement.
Data obtained from Google APIs is not sent to any AI or machine learning service. The Google Calendar connection described in section 6 is separate from the features above: the appointment records it creates are not readable by the in-app assistant or by any other AI feature, and no Google user data, raw or derived, is transferred to an AI provider for any purpose, including model training.
We use cookies that are necessary for the Service to work, such as keeping you signed in and protecting against fraud. These cannot be switched off without breaking the Service.
On our public pages, meaning our marketing site and our pricing, booking, contact and sign-up pages, we also use Google Analytics and the Meta (Facebook) advertising pixel to understand how people find us, which pages they read, and which advertisements bring them here. These record the pages viewed, the site or advertisement you arrived from, an approximate location derived from your IP address, and basic device and browser information. We read them in aggregate to improve the site and to measure our advertising.
Neither is loaded inside the signed-in application or the client portal. Addresses in those areas can identify a particular return, client, case or portal session, and we do not send them to any analytics provider. Nothing you or your clients enter into a tax return, a document, a message or the portal is ever sent to Google Analytics.
You can opt out at any time through your browser's cookie settings, or by installing Google's official opt-out add-on at tools.google.com/dlpage/gaoptout. Declining analytics does not limit your use of the Service.
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest for sensitive fields, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We maintain a written information security program covering the safeguards required of tax professionals, including those in IRS Publication 4557 and the FTC Safeguards Rule. If we become aware of a breach affecting your information or your clients' information, we will notify you without undue delay and provide the detail you need to meet your own notification obligations.
We retain account and taxpayer information for as long as your account is active and as needed to provide the Service. After account termination, we retain Your Data for 30 days to allow export, after which it is deleted unless a longer period is required by law (including tax recordkeeping requirements) or our Data Processing Agreement.
You may access, correct, export, or request deletion of your account information by contacting us. Depending on your state of residence, you may have additional rights under applicable privacy laws. Requests concerning a Customer's own client data are handled under the Data Processing Agreement.
The Service is intended for use by tax professionals and is not directed to children under 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. Your continued use of the Service after changes take effect constitutes acceptance.
TaxPulse Incorporated
Fajardo, Puerto Rico
Email: support@taxpulse.biz
Phone: (787) 468-3300